cyberversicherung.ch

Reporting Cyber Attacks in Switzerland: FADP, BACS and Emergency Plan

Published: Updated: Reading time: 5 min

The short answer

A practical guide to Swiss cyber incident reporting: Article 24 FADP, the 24-hour BACS duty for covered critical infrastructure and a ten-step response plan.

Two duties that must not be confused

A cyber incident does not automatically trigger the same notification for every organisation. Two federal regimes are particularly important:

  1. Under Article 24 of the Federal Act on Data Protection (FADP), a controller must notify the Federal Data Protection and Information Commissioner (FDPIC) as quickly as possible if a data security breach is likely to result in a high risk to the personality or fundamental rights of affected persons.
  2. Since 1 April 2025, covered operators of critical infrastructure must report certain cyber attacks to the Federal Office for Cybersecurity (BACS) within 24 hours of discovery.

The Swiss FADP does not prescribe a general 72-hour deadline. The BACS 24-hour rule does not apply to every Swiss business. Sector-specific or contractual duties may apply in addition.

RegimeRecipientTimingScope
FADP Art. 24FDPICAs quickly as possibleData security breach likely to create a high risk
BACS reporting dutyBACSWithin 24 hours of discoveryCovered critical-infrastructure operators and reportable cyber attacks
Sector rulesCompetent regulatorDepends on the applicable ruleFor example, regulated financial or health-sector organisations

Article 24 FADP: when notification is required

A data security breach can involve the loss, deletion, destruction or alteration of personal data, or unauthorised disclosure of or access to it. The controller must assess whether the breach is likely to create a high risk for affected persons.

Relevant factors can include:

  • the sensitivity and volume of the personal data
  • whether the data can facilitate identity theft, discrimination or financial harm
  • the number and vulnerability of affected people
  • whether data was encrypted or otherwise effectively protected
  • the likely consequences and the ability to limit them

The notification to the FDPIC must contain the available information required by law, including the nature and consequences of the breach and the measures taken or planned. If complete information is not yet available, the organisation should document its assessment and seek qualified advice rather than wait for certainty.

Affected persons must be informed when this is necessary for their protection or when the FDPIC requires it. This is a separate assessment from the notification to the authority.

FADP sanctions: no automatic CHF 250,000 fine for a late report

The FADP provides fines of up to CHF 250,000 for specified intentional offences, generally directed at natural persons. A late or omitted Article 24 notification does not automatically produce a CHF 250,000 fine. The FDPIC may investigate and order measures; intentionally disobeying a legally binding order can be punishable.

Legal exposure depends on the actual provision and conduct. It should not be reduced to a blanket fine claim.

BACS reporting for critical infrastructure

The BACS duty applies only where both the organisation and the incident fall within the statutory scope. The official BACS guidance lists covered sectors, exemptions and reportable criteria.

The initial report is due within 24 hours after discovery. It need not contain every forensic detail. Information that was not available for the initial report can generally be added within 14 days.

The BACS semi-annual report published in March 2026 recorded 325 mandatory reports from the introduction of the duty on 1 April through the end of 2025. This figure is not the total number of Swiss cyber attacks.

Enforcement is graduated

The maximum fine of CHF 100,000 is not an automatic penalty at the 24-hour mark. According to BACS, the sequence is graduated: an organisation is first informed of the suspected reporting duty; if it still does not report, BACS may issue an order with a penalty warning; continued intentional non-compliance with the binding order can lead to criminal proceedings.

Ten-step incident checklist

  1. Activate the response team: assign decision-making, technical, legal and communication roles.
  2. Protect people and operations: contain the incident with competent technical support; do not apply a universal shutdown rule without assessing safety and evidence.
  3. Record the timeline: document discovery time, affected systems, decisions and available logs.
  4. Preserve evidence: secure relevant logs, messages and system images without unnecessarily altering them.
  5. Assess data impact: identify the personal data, people and likely consequences involved.
  6. Check all duties: assess FADP, BACS, sector, contractual and cross-border requirements in parallel.
  7. Submit time-critical reports: use verified facts, state uncertainties and supplement information where permitted.
  8. Communicate safely: tell affected persons when required and coordinate accurate internal and external messages.
  9. Recover deliberately: restore from trusted sources, validate systems and monitor for persistence.
  10. Review and improve: record the cause, control gaps, notification decisions and corrective actions.

Filing a criminal complaint may be appropriate, particularly for extortion, fraud or unauthorised access, but it is not a universal reporting duty for every cyber incident.

How cyber insurance may assist

Depending on the policy and prior approval requirements, incident-response providers, IT forensics, legal advice, notification costs, crisis communication or business interruption may be insured. Availability, response times and reimbursement are governed by the actual contract; fines are not automatically insurable or covered.

Before an incident, check the hotline, approved providers, reporting process, sublimits and the point at which cover is triggered. The organisation remains responsible for meeting its legal duties.

Sources

BTAG Versicherungsbroker AG · Bern

Have questions about cyber insurance?

BTAG clarifies your risk profile and discloses any commission before conclusion. The request does not oblige you to buy.

Quote advice by BTAG Versicherungsbroker AG, Bern — FINMA-registered insurance intermediary.

Verified primary sources
Transparent compensation